‘Past approaches to resilience testing no longer work’, warns Spirent VP

Anil Kollipara, vice president of product management at Spirent Communications

As regulators tighten expectations around operational resilience, QA and software testing teams at banks are being pushed deeper into the mechanics of network reliability, compliance and risk mitigation.

Anil Kollipara, Vice President of Product Management at Spirent Communications, argues that automated network testing is no longer optional for financial services firms operating in complex, distributed environments.

For Kollipara, the stakes are clear. “For financial services firms, a secure, resilient, compliant network infrastructure has long been a top imperative,” he stated.

“Today, as digital transformation upends traditional IT supply chains and new cyber threats emerge, the stakes are even higher.”

He added that “even a short outage caused by cyberattacks, software updates, or supply chain failures can disrupt essential services, putting customers at risk, damaging reputations, and impacting the bottom line.”

Kollipara pointed to the real-world consequences of inadequate testing, noting that “in 2024, the CrowdStrike outage caused by a software update error cost the banking sector an estimated $1.15 billion.”

Regulation raises the bar

Kollipara framed the current wave of regulatory scrutiny as a direct response to rising systemic risk. “As risks grow and the pace of change accelerates, government and industry regulators are responding with new regulations to protect the reliability of critical infrastructure,” he explained.

Kollipara highlighted the impact of Europe’s Digital Operational Resilience Act, explaining that “the Digital Operational Resilience Act (DORA), introduced by the European Union, became active in January 2025.”

“DORA is designed to ensure that financial services firms can respond to and recover from cyberattacks and other disruptions,” he stressed, while also mandating that institutions “report incidents within hours and conduct operational security resiliency testing.”


“Manually created test cases and sporadic testing can take months.”

– Anil Kollipara

From a QA perspective, Kollipara stressed that the regulation goes beyond surface-level checks.

“DORA also defines stringent test methodologies, from network security and vulnerability assessments to end-to-end information and communication technology testing,” he said.

Therefore, Kollipara issued a firm warning, saying that “organisations that fail to comply could face fines, remediation, and violation reports.”

The limits of manual testing

Kollipara argued that compliance expectations are colliding with an infrastructure reality that is far harder to test using traditional methods.

“Although compliance testing is a critical process for strengthening network resilience and business continuity, today’s enterprise environments are increasingly distributed and diverse,” he said.

“Workloads and storage are no longer isolated in the data centre but extend across multiple sites and cloud environments.”

Kollipara went on to say that “the traditional network perimeter has become a thing of the past, and gaining visibility, managing, and protecting these distributed environments is more complex than ever.”

In his view, “the challenges only escalate when it’s time to introduce new technologies into these fast-changing, complex environments.”


“It’s clear that past approaches to resilience testing can no longer meet today’s expectations.”

– Anil Kollipara

That complexity is exposing the weaknesses of legacy testing approaches.

“As digital transformation redefines enterprise networks, it’s clear that past approaches to resilience testing can no longer meet today’s expectations,” Kollipara continued.

While vendors once carried much of the burden, he noted that “in this dynamic environment, vendor testing alone is not sufficient; it’s up to financial services organisations to take responsibility for assuring end-to-end resilience across their infrastructures.”

Manual testing, Kollipara argued, simply cannot keep up. “Manually created test cases and sporadic testing can take months, making it difficult to keep pace with changes and increasing the risk of incidents and outages,” he said.

The industry veteran added that “traditional testing methodologies are not integrated into a continuous integration/continuous delivery (CI/CD) pipeline, making it challenging to validate changes seamlessly.”

As a result, “today’s complex, fast-changing enterprise networks require new tools to efficiently and cost-effectively test the resilience of today’s test loads at scale.”

Reshaping resilience testing

For Kollipara, automation is the foundation of a modern resilience strategy. “A strategy based on test process automation is essential,” he said.

“Automation empowers organisations to support the speed, scale, and accuracy that complex distributed enterprises demand.”

Kollipara added that “automation also lets organisations test multiple scenarios continuously,” which he describesdas critical because “a robust approach to operational resiliency should support continuous testing, from lab environments to live deployments.”

Kollipara emphasised that network changes cannot be treated in isolation. “In a complex supply chain, even a small change in the network could disrupt operations,” he stressed.

“Changes should be tested automatically, considering the full context and variables of the entire network and its traffic, before being deployed to production.”


“Digital twins also facilitate testing by simulating real-world scenarios to test operational resilience accurately.”

– Anil Kollipara

Traditional tools, Kollipara went on to say, are simply not fit for this purpose. “Most traditional testing technologies and scripts aren’t designed to evaluate network resilience,” he said, concluding that “specialised tools like emulators and digital twins will be required.”

According to Kollipara, “emulators enable IT to vary test traffic, without the time and expense needed to create a test network in a lab,” while “digital twins also facilitate testing by simulating real-world scenarios to test operational resilience accurately.”

AI, he believes, is becoming an accelerator rather than a risk. “AI is unlocking exciting outcomes across every industry, and resilience testing is a powerful showcase for its capabilities,” Kollipara shared.

He noted that AI “can enhance efficiency by making more innovative test selections,” while also speeding up diagnostics, as “the technology can also accelerate root cause analysis by quickly identifying the exact cause of failures.”

Competitive advantage

Kollipara concluded that automated, continuous resilience testing can help financial institutions move beyond defensive compliance.

“Financial services remain a competitive, fast-moving market environment where minimising risk is paramount,” he said.

By adopting automation-led testing, he argues, firms “can mitigate risk, meet their compliance mandates, and maximise business continuity.”

Just as importantly for QA and testing leaders, he says this approach can unlock innovation.

Organisations can “free their IT teams to work more efficiently, innovate faster, and deliver new products, services, and value to their customers,” while keeping resilience and regulatory expectations firmly under control, Kollipara concluded.


COMING IN 2026



Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS